forked from rubenslte/android_kernel_samsung_msm8226
ASoC: q6lsm: Add check for integer overflow
During sound model registration, the total memory size needed by the sound model data is the sum of sound model length, number of zero padding bytes and the calibration size. It is possible this sum can result into integer overflow causing difficult to debug issues. Add check for integer overflow to avoid such possible issues. CRs-fixed: 792367 Change-Id: I9f451aa308214a4eac42b82e2abf1375c858ff30 Signed-off-by: Bhalchandra Gajare <gajare@codeaurora.org> CVE-2015-8940 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
ffac186c6e
commit
ace2a1b716
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (c) 2013-2014, Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2013-2015, Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -740,6 +740,15 @@ int q6lsm_snd_model_buf_alloc(struct lsm_client *client, size_t len)
|
||||
client->sound_model.size = len;
|
||||
pad_zero = (LSM_ALIGN_BOUNDARY -
|
||||
(len % LSM_ALIGN_BOUNDARY));
|
||||
if ((len > SIZE_MAX - pad_zero) ||
|
||||
(len + pad_zero >
|
||||
SIZE_MAX - lsm_cal.cal_size)) {
|
||||
pr_err("%s: invalid allocation size, len = %zd, pad_zero =%zd, cal_size = %zd\n",
|
||||
__func__, len, pad_zero,
|
||||
lsm_cal.cal_size);
|
||||
rc = -EINVAL;
|
||||
goto fail;
|
||||
}
|
||||
total_mem = pad_zero + len + lsm_cal.cal_size;
|
||||
pr_debug("%s: Pad zeros sound model %d Total mem %d\n",
|
||||
__func__, pad_zero, total_mem);
|
||||
|
||||
Reference in New Issue
Block a user